Privacy Policy

Last updated: 24 July 2026

This Policy is maintained by VendyGate to explain what personal and organizational information the Platform collects, why, and how it is protected. Shared responsibility applies: VendyGate operates the Platform's technical controls; account custodians are responsible for the accuracy of data they upload and for keeping their credentials safe.

1. What we collect

  • Account data — email, password (hashed), name, phone, position/title.
  • Organization data — company name, industry, address, registration number, TIN.
  • Compliance documents — files you upload as a vendor (e.g., incorporation, tax clearance) with type, number, and expiry metadata.
  • Tender and bid data — tenders you post, bids you submit, service inquiries you send.
  • Technical data — session tokens, IP addresses, and error logs used to operate the service.

2. Why we use it

  • To operate accounts, verification, tender posting, and bidding.
  • To let counterparties assess each other in the context of an active bid or inquiry.
  • To detect fraud and abuse.
  • To comply with legal obligations.

3. Who can see what

  • You can see everything on your own account.
  • The public / signed-in users see only a trimmed profile (name, company, verification status; for service providers: name, bio, hourly rate, experience).
  • Companies can view a vendor's compliance documents that the vendor has marked "companies" or "public" tier, whether or not that vendor has bid on their tender. Documents marked "private" (including banking details, which are always private) are hidden unless the vendor separately approves a direct access request from that company.
  • Sensitive tender data (budget, requirements) is only visible to the posting company and the vendors bidding on that tender.
  • Service providers can see inquiries addressed to them.

These rules are enforced at the database layer using row-level security policies, not just in the user interface.

4. Storage and security

Data is stored on Lovable Cloud infrastructure with encryption in transit (HTTPS/TLS) and at rest. Compliance documents are stored in a private storage bucket that is not directly accessible from the internet; downloads are served via short-lived signed URLs. Passwords are hashed and are never visible to us. Passwords are checked against known-breached password lists at signup to reduce credential-stuffing risk.

This description reflects controls currently enabled on the Platform. It is not an independent certification.

5. Retention

Account and compliance data is retained while your account is active. If you close your account, we delete personal data within a reasonable period unless we must retain records to meet legal or dispute-resolution requirements.

6. Your rights

You may request access, correction, or deletion of your personal data by writing to privacy@vendygate.com. You can also update most of your data directly in the app.

7. Subprocessors

We use trusted infrastructure providers (Lovable Cloud, Supabase, Cloudflare) to host and operate the Platform. We do not sell your data.

8. Contact

Privacy questions: privacy@vendygate.com.